Description* Changed CajitaRewriter.java and Rule.java to whitelist expressions of the
form @o[@s & -1 <<< 1] instead of @o[+@s]
* Changed cajita.js to check that index > 0 when allowing numeric reads
* Added tests to CajitaRewriterTest and domita_test_untrusted.html to
check that neither Rhino nor the browser return anything but undefined
on reading a negative index.
* Updated structural tests in CajitaTest.java
* Fixes bug 1093
Patch Set 1 #
Total comments: 7
Patch Set 2 : Restrict numeric whitelisting to nonnegative integers. #Patch Set 3 : Restrict numeric whitelisting to nonnegative integers. #
Total comments: 4
MessagesTotal messages: 8
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||